← Advisories

Infoproject Biznis Heroj (XSS/SQLi) Multiple Remote Vulnerabilities

Medium
Advisory ID
ZSL-2011-5064
Release Date
21 December 2011
Vendor
Infoproject DOO - http://www.biznisheroj.mk
Affected Version
Plus, Pro and Extra
Tested On
Apache, PHP
Summary

Biznis Heroj or Business Hero is the first software on the Macedonian market that will help you manage your business processes in your company, such as accounting, production, acquisition, archiving, inventory, and the Cloud. Using the Cloud technology, Biznis Heroj allows you to access the system from any computer at any time through any internet browser.

Description

Input passed via the parameters 'filter' in 'widget.dokumenti_lista.php' and 'fin_nalog_id' in 'nalozi_naslov.php' script are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The param 'config' in 'nalozi_naslov.php' and 'widget.dokumenti_lista.php' is vulnerable to a XSS issue where the attacker can execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Proof of Concept
Disclosure Timeline
14.12.2011Vulnerability discovered.
15.12.2011Contact with the vendor.
20.12.2011No response from the vendor.
21.12.2011Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
21.12.2011Initial release
22.12.2011Added reference [4] and [5]
24.12.2011Added reference [6] and [7]
15.01.2012Added reference [8], [9], [10], [11], [12] and [13]